7-6
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter 7 Defining Signatures
Configuring Signatures
Configuring Signatures
This section describes how to configure signature parameters, and contains the following topics:
Signature Definition Options, page 7-6
Configuring Alert Frequency, page7-7
Configuring Alert Severity, page7-9
Configuring the Event Counter, page 7-10
Configuring Signature Fidelity Rating, page 7-12
Configuring the Status of Signatures, page 7-13
Configuring the Vulnerable OSes for a Signature, page 7-14
Assigning Actions to Signatures, page 7-15
Configuring AIC Signatures, page 7-17
Configuring IP Fragment Reassembly, page7-28
Configuring TCP Stream Reassembly, page 7-31
Configuring IP Logging, page 7-39

Signature Definition Options

The following options apply to configuring the general parameters of a specific signatu re:
alert-frequency—Sets the summary options for grouping alerts.
alert-severity—Sets the severity of the alert .
engine—Specifies the signature engine. You can assign actions when you are in the engine
submode.
event-counter—Sets the event count.
promisc-delta—Specifies the delta value used to determine the seriousness of the alert.
Caution
We recommend that you do NOT change the promiscuous delta setting for a signature.
Promiscuous delta lowers the risk rating of certain alerts in promiscuous mode. Because the sensor
does not know the attributes of the target system and in promiscuous mode cannot deny packets, it
is useful to lower the prioritization of promiscuous alerts (based on the lower risk rating) so the
administrator can focus on investigating higher risk rating alerts.
In inline mode, the sensor can deny the offending packets and they never reach the target h ost, so it
does not matter if the target was vulnerable. The attack was not allowed on the network and so we
do not subtract from the risk rating value.
Signatures that are not service, OS, or application specific have 0 for the promiscuous delta. If the
signature is specific to an OS, service, or application, it has a promiscuous delta of 5, 10, or 15
calculated from 5 points for each category.
sig-description—Your description of the signature.
sig-fidelity-rating—Specifies the rating of the fidelity of signature.
status—Sets the status of the signature to enabled or retired.